Active frameworks
CertiFlow is itself in active build-out against these frameworks. SOC 2 Type I attestation is the next milestone. The platform powers our own evidence vault.
Security posture — what an attacker can take
| Scenario | What an attacker obtains |
|---|---|
| Lawful court order, customer-specific | Ciphertext + plaintext metadata only |
| Production database breach | Ciphertext only at rest |
| Out-of-band backup vault breach | Ciphertext only at rest |
| Compromised CertiFlow insider with root | Metadata only; cannot decrypt evidence |
Full threat model and ZKE architecture detail: Security page.
Operational posture
Documents
- Data Processing Agreement (DPA) — includes Annex III ZKE clauses
- Sub-processor disclosure list — under ZKE, materially shorter than incumbents
- Privacy notice
- Security page — ZKE + 8-layer defence
Need deeper access for an audit?
External auditors can be invited to a read-only Auditor View scoped to the controls in their engagement — every page-view, every comment, every export is recorded in the tamper-evident audit chain. Email trust@certiflow.com with your organisation name and your auditor’s firm name.